fix: sanitize hyperlink OSC output (#29) (thanks @mafulafunk)

This commit is contained in:
Peter Steinberger
2026-01-11 11:11:21 +00:00
parent 837b09fcad
commit 0a4699711f
3 changed files with 11 additions and 1 deletions
+1
View File
@@ -4,6 +4,7 @@
### Fixed ### Fixed
- macOS cookie extraction now supports Brave keychain storage (#40) — thanks @gakonst. - macOS cookie extraction now supports Brave keychain storage (#40) — thanks @gakonst.
- Terminal hyperlinks now sanitize control characters before emitting OSC 8 sequences (#29) — thanks @mafulafunk.
- Following/followers pagination now guards repeat cursors and standardizes JSON output (#28) — thanks @malpern. - Following/followers pagination now guards repeat cursors and standardizes JSON output (#28) — thanks @malpern.
- Lists GraphQL feature flags updated to prevent 400s (#27) — thanks @zheli. - Lists GraphQL feature flags updated to prevent 400s (#27) — thanks @zheli.
- Likes pagination now follows cursors and avoids stalling on duplicate pages (#12) — thanks @titouv. - Likes pagination now follows cursors and avoids stalling on duplicate pages (#12) — thanks @titouv.
+3 -1
View File
@@ -106,8 +106,10 @@ export function hyperlink(url: string, text?: string, cfg?: OutputConfig): strin
if (!cfg?.hyperlinks) { if (!cfg?.hyperlinks) {
return displayText; return displayText;
} }
const safeUrl = url.replaceAll('\x1b', '').replaceAll('\x07', '');
const safeText = displayText.replaceAll('\x1b', '').replaceAll('\x07', '');
// OSC 8 hyperlink: \x1b]8;;URL\x07TEXT\x1b]8;;\x07 // OSC 8 hyperlink: \x1b]8;;URL\x07TEXT\x1b]8;;\x07
return `\x1b]8;;${url}\x07${displayText}\x1b]8;;\x07`; return `\x1b]8;;${safeUrl}\x07${safeText}\x1b]8;;\x07`;
} }
export function formatTweetUrlLine(tweetId: string, cfg: OutputConfig): string { export function formatTweetUrlLine(tweetId: string, cfg: OutputConfig): string {
+7
View File
@@ -111,4 +111,11 @@ describe('output', () => {
expect(result).toContain('Click here'); expect(result).toContain('Click here');
expect(result).toContain('\x1b]8;;https://x.com/test\x07'); expect(result).toContain('\x1b]8;;https://x.com/test\x07');
}); });
it('hyperlink strips OSC control characters from url and text', () => {
const cfg = { plain: false, emoji: true, color: true, hyperlinks: true };
const result = hyperlink('https://x.com/\u001btest\u0007', 'Hi\u001b\u0007', cfg);
expect(result).not.toContain('\u001btest\u0007');
expect(result).not.toContain('Hi\u001b\u0007');
});
}); });